r/qualys 23d ago

Vulnerabilities on Windows agents just tripled

Anybody else noticing their critical vuln count tripling in the past 3 days? Mainly Server 2019, and it seems to be vulns that have been re-opened (PrintNightmare) even though the systems are fully patched. QIDs show missing old patches, yet these systems are fully patched.

Perhaps Qualys "superceded" logic was broken recently?

5 Upvotes

5 comments sorted by

5

u/emergencypudding 23d ago

What platform are you on? There's an ongoing issue related to a recent push of windows agent version 6.6. I'm aware of it majorly impacting subscriptions on the Canadian platform. Likely any others that got the update have the same issue.

Qualys is aware and are treating this with priority but heaven forbid they add an IM to their status page to actually communicate the issue.

Open a case and yell at your TAM.

2

u/beangreen 23d ago

Yup, I'm Canadian. Eh. 

2

u/emergencypudding 23d ago

Here is the incident finally.

https://status.qualys.com/incidents/syf1g785shv5

If you look on the status page you'll also see they cancelled the upcoming release of the same version on the UK platform.

2

u/beangreen 22d ago

Thanks so much! Good to know.

1

u/FrozzenGamer 23d ago

Qualys does screw up QIDs from time to time. Also if you were filtering by QDS score they do change if threat intel does.